Description
Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
Any version before 1.24.0190
Any version before 6.61.0010
Any version before 6.61.0010
Any version before 6.61.0010
Credits
Dariusz Gońda
References
cert.pl/posts/2026/02/CVE-2025-14577
www.slican.pl/oferta/centrale-telefoniczne/